Based on information from The Hacker News, researchers have discovered a method to leverage a legitimate Windows Defender driver for kernel-level file and registry operations on Windows systems, without exploiting any software flaws.Check Point Research disclosed a technique that uses Microsoft Defender's boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level file and registry operations on Windows 7 through Windows 11 25H2. This method does not exploit software vulnerabilities and uses a driver already present on the system. The driver, embedded within Defender's MpEngine.dll, is designed to remove malware components locked during system operation. Researchers reverse-engineered its undocumented transaction protocol, finding it uses RC4 encryption with a hard-coded key. A proof-of-concept tool, BTR_CLI, can extract the driver, construct encrypted transactions, and install it as a service, bypassing standard service management and logging.Once loaded, BTR.sys executes operations from Ring 0, allowing it to delete or move files, and modify registry entries. It can even remove security binaries like Defender's own components during a specific "golden window" after the file system is writable but before Defender's user-mode services start. Exploitation requires administrator privileges with SeLoadDriverPrivilege. Microsoft has stated that this technique does not meet the criteria for immediate servicing as it relies on pre-existing administrative access. While not observed in real-world attacks, the technique highlights an architectural trust boundary that can be exploited by an attacker with sufficient privileges.Source: The Hacker News
Endpoint/Device Security
Researchers find way to weaponize Windows Defender’s own driver
(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
